Several major data breach class action settlements reached their deadline in July 2026, creating a critical window for affected consumers to file claims before compensation payments are finalized. By the end of July, most of these deadlines had already passed—including the Fidelity Investments settlement (July 27), Union Bank & Trust breach (July 21), South Texas Oncology settlement (July 6), SAG-AFTRA Health Plan breach (July 23), Alabama Ophthalmology settlement (July 6), and the Bray International settlement (July 30). These settlements represent millions of dollars in compensation for consumers whose personal and financial information was compromised in various breaches dating back to 2023 and 2024. For consumers who missed July deadlines, time to claim is now expired for most of these breaches.
However, one significant settlement—the Comcast Xfinity data breach settlement—extended its deadline to September 14, 2026, offering affected customers a second chance to file claims. Understanding which settlements have closed and which remain open is essential for anyone who may have been impacted by these major breaches affecting healthcare patients, financial customers, entertainment union members, and millions of broadband subscribers. The stakes are substantial. The Comcast settlement alone represents $117.5 million in potential payments to approximately 36 million customers, while smaller settlements like the SAG-AFTRA Health Plan ($950,000) and South Texas Oncology ($1.075M) have attracted proportionally larger individual payouts. For those who missed the July deadlines, understanding the implications—including whether appeals or additional filing periods might still be available—requires knowing the specifics of each settlement.
Table of Contents
- What Data Breaches Led to July 2026 Settlement Deadlines?
- Who Could Claim and How Much Was Each Settlement Worth?
- Why Did Most Deadlines Fall in July 2026?
- What Happened to Missed Deadlines?
- Documentation Requirements and Proof Challenges
- The Comcast Exception and Extended Timeline
- Lessons and Future Claim Tracking
What Data Breaches Led to July 2026 Settlement Deadlines?
The July 2026 settlement deadlines stemmed from breaches occurring across multiple industries between 2023 and 2024. The most widely publicized was the Comcast Xfinity breach, which occurred on October 16–19, 2023, but wasn’t disclosed until December 18, 2023. That breach exposed credentials and customer account information for approximately 36 million Xfinity customers. A separate and substantial breach affected Fidelity Investments customers in August 2024, compromising approximately 77,000 confirmed individuals out of 160,000 total Fidelity account holders, exposing names, addresses, and financial information. healthcare providers also featured prominently in the July settlements. South Texas Oncology & Hematology detected a breach on February 15, 2024, ultimately affecting 175,195 patients whose protected health information (PHI) was exposed.
Similarly, Alabama Ophthalmology experienced a breach in January 2025 affecting approximately 150,000 patients. The SAG-AFTRA Health Plan suffered a phishing and email-based breach on September 17–18, 2024, compromising beneficiary health records. These breaches underscore the vulnerability of both financial institutions and healthcare providers to sophisticated attacks, with healthcare particularly susceptible to ransomware and targeted credential theft. The Union Bank & Trust settlement stemmed from a MOVEit file transfer vulnerability breach occurring May 27–31, 2023, affecting 204,291 individuals. The Bray International breach, detected in April 2024, exposed names, Social Security numbers, and driver’s license numbers, though the exact number of affected individuals was not publicly disclosed. Each breach involved different attack vectors—some leveraging known software vulnerabilities (MOVEit), others involving phishing or ransomware—but all resulted in substantial exposure of personally identifiable information or sensitive financial data.
Who Could Claim and How Much Was Each Settlement Worth?
Settlement amounts and individual payout potential varied significantly, with the Comcast settlement being substantially larger than others. The $117.5 million Comcast settlement offered affected customers either a flat $50 payment or up to $10,000 for documented losses, which could include fraud, credit monitoring fees, or time spent resolving identity theft. For the 36 million potentially eligible Xfinity customers, even the flat $50 payout represented a significant aggregate commitment. The fidelity settlement, worth $2.5 million, offered up to $5,000 for documented losses or approximately $100 pro rata, plus $50 additional compensation for California residents and two years of complimentary credit monitoring.
The Union Bank & Trust settlement of $2.39 million provided $100 cash payments or up to $10,000 for documented losses to 204,291 affected individuals, making it more generous on a per-person basis than either the Fidelity or Comcast flat payments. The South Texas Oncology settlement ($1.075M) offered similar terms: up to $5,000 for documented losses or approximately $100 pro rata, with credit monitoring included. The Bray International settlement allowed for $45 flat payments or up to $3,000 for extraordinary losses. SAG-AFTRA Health Plan settlement ($950,000) provided pro rata cash payments and up to $5,000 for documented losses. A critical limitation is that all of these settlements required documentation of actual financial harm to qualify for the higher compensation amounts—meaning consumers without receipts, credit reports showing unauthorized charges, or evidence of time spent resolving identity theft typically received only the lower pro rata or flat payment.
Why Did Most Deadlines Fall in July 2026?
The concentration of July 2026 deadlines was not coincidental but reflected the scheduling practices of settlement administrators and courts. Once a settlement is reached and preliminary approval is granted, courts typically establish a claims period of 60 to 120 days for affected consumers to submit claims. The final approval hearing—where a judge certifies the settlement and resolves any objections—typically occurs 30 to 60 days after the claims deadline. For settlements with breaches disclosed in late 2023 or early 2024, litigants negotiated and approved settlements throughout late 2025 and early 2026, resulting in claims deadlines cascading through June and July 2026.
The Union Bank & Trust settlement, for example, had its final approval hearing scheduled for August 6, 2026—just two weeks after the July 21 claims deadline—indicating that the court calendar had already been set months in advance. The SAG-AFTRA Health Plan’s final approval hearing was scheduled for September 24, 2026, well after its July 23 claims deadline expired, meaning objections and claim disputes would be resolved after the deadline had passed. This temporal staggering meant that consumers who became aware of settlements only in mid-to-late July had little time to gather documentation, complete claim forms, and submit before deadlines closed. The Comcast exception—with its extended September 14 deadline—occurred because the original August 14 deadline proved inadequate, likely due to high claim volumes or administrative concerns about adequate notice to the full 36 million-person class.
What Happened to Missed Deadlines?
For the six settlements with July 2026 deadlines that have now passed, the claims windows are definitively closed. The Fidelity, Union Bank & Trust, South Texas Oncology, SAG-AFTRA Health Plan, Alabama Ophthalmology, and Bray International settlements no longer accept new claims as of July 30, 2026. Consumers who did not file by the deadline cannot retroactively submit claims, though limited exceptions exist in rare circumstances. Some settlement agreements include a “late claim” provision allowing claims submitted within 30 to 90 days after the deadline if the claimant can demonstrate excusable neglect—typically requiring evidence that they received notice too late or faced extraordinary circumstances preventing timely filing.
However, these exceptions are narrowly construed and rarely granted; most settlement administrators make no provision for late claims whatsoever. The practical consequence is that missed deadlines often mean forfeited compensation. Claims that were not filed by July 30, 2026, for settlements like Fidelity or South Texas Oncology are no longer valid, and affected individuals have no recourse to recover settlement payments. This creates a tradeoff between the settlement administrator’s need to close out claims and distribute remaining funds versus fairness to consumers who may have had legitimate obstacles to timely filing. For the Comcast settlement with its September 14 extended deadline, consumers still have until mid-September 2026 to file, providing a final window for the largest breach affecting millions of broadband customers.
Documentation Requirements and Proof Challenges
One of the most significant barriers to receiving larger payouts from these settlements was the documentation requirement. To claim up to $5,000 or $10,000 in documented losses rather than the flat pro rata payment, consumers needed to prove actual financial harm. Acceptable documentation typically included credit card statements showing unauthorized charges, identity theft reports filed with the Federal Trade Commission, credit monitoring bills paid out of pocket, or documented time spent resolving fraudulent accounts. For healthcare breaches like South Texas Oncology or Alabama Ophthalmology, consumers could claim losses related to fraudulent medical billing or identity theft using their medical identity.
The limitation here is that many consumers affected by data breaches never experience any direct financial loss, particularly in the years immediately following disclosure. A consumer whose Social Security number was stolen may never see fraudulent activity, especially if credit monitoring services provided by the settlement prevented unauthorized account creation. In those cases, consumers were limited to the flat pro rata payment of $50 to $100, significantly less than the documented loss maximum. Additionally, settlement administrators often requested documentation months after the breach occurred, by which time consumers may have discarded credit card statements or forgotten to save identity theft reports. Consumers who could not locate supporting documents faced the burden of requesting duplicate statements from financial institutions or credit agencies, a process that added friction and discouraged claims.
The Comcast Exception and Extended Timeline
The Comcast Xfinity settlement stands apart due to its substantially extended deadline and magnitude. Originally scheduled for August 14, 2026, the deadline was pushed to September 14, 2026, providing an additional month for the 36 million potentially affected customers to file claims. This extension suggests that Comcast and the settlement administrator anticipated either high claim volumes, insufficient notice to the full class, or logistical challenges in processing claims within the standard timeframe.
The $117.5 million settlement dwarfs the others—Comcast’s payout is larger than all six other July 2026 settlements combined. For consumers who use Xfinity internet or television, the claim process typically required verifying account ownership and submitting documentation of any losses incurred due to identity theft or fraudulent account creation following the October 2023 breach. Given the breach’s scope and the breadth of potentially affected customers, Comcast settlement administrators anticipated that many claimants would be less sophisticated than financial services customers or healthcare patients and therefore required more time to process claims. The September 14 deadline gave consumers who discover the settlement in August an opportunity to file, though with only weeks to gather documentation.
Lessons and Future Claim Tracking
For consumers navigating future data breach settlements, the July 2026 deadline rush offers instructive lessons. First, settlement deadlines typically appear in press coverage but are easily missed in the noise of day-to-day news. Subscribing to breach notification services like HaveIBeenPwned.com or monitoring official settlement websites (like FidelityDataSettlement.com or UBTDataSettlement.com) provides advance notice of claim deadlines. Second, waiting until the final week before a deadline to gather documentation substantially increases the risk of missing the window—settlement administrators report that the majority of late claims and incomplete submissions occur in the final 10 days before closure, when claimants belatedly rush to file.
Third, the documentation required for larger payouts should be collected and retained immediately after breach disclosure or after claiming credit monitoring services. Consumers who discover a breach should pull credit reports, document any fraudulent activity, and retain records of time and expense spent resolving identity theft. Without contemporaneous documentation, proving losses months later becomes difficult. Finally, checking whether your state was disproportionately affected by a breach can matter; some settlements, like Fidelity’s, included state-specific bonuses (the $50 CCPA payment for California residents), which altered payout calculations. For the now-closed July settlements, these lessons apply to learning from missed opportunities; for the still-open Comcast settlement with its September 2026 deadline, they represent actionable steps to maximize recovery.
